Retour au Trust Center
Disponible uniquement en anglais. Ce document juridique est fourni en anglais en tant que version faisant foi. L'interface du Trust Center est traduite dans votre langue.

Customer-facing legal documents — change log

Cumulative summary of revisions to the four customer-facing legal documents in this folder (PRIVACY-POLICY.md, DATA-PROCESSING-AGREEMENT.md, REGISTER-OF-PROCESSING-ACTIVITIES.md, TERMS-OF-SERVICE.md).

This file is append-only. Each revision adds a new dated entry at the top; older entries are never edited or removed. The most recent entry is the current state.

For the binding documents themselves, see the trust center: https://trust.ismscopilot.com/privacy-policy, https://trust.ismscopilot.com/dpa, https://trust.ismscopilot.com/ropa, https://trust.ismscopilot.com/terms.

Sub-processor and data-handling changes are notified per DPA §2.4: through (a) the Trust Center, (b) the in-app changelog (with blue-point unread indicator on next login), (c) this change log, and (d) the regular customer product-update / changelog email. For materially-adverse changes (a new sub-processor with a new retention or jurisdiction posture, a weakening of an existing control, etc.), ISMS Copilot will provide at least 30 days' advance notice by in-app announcement and email. For control-neutral sub-processor changes (adding a vetted provider to an existing closed allowlist where the same zero-retention, no-training, transfer-mechanism, and jurisdiction-blocking controls continue to apply), notice is via Trust Center publication and in-app changelog. A more detailed internal change record for each sub-processor change is available on request via privacy@ismscopilot.com.


Documents added: the ISMS Copilot Partner Embed legal set, published as its own product-scoped Trust Center pages, distinct from the chat product's documents: Partner Terms of Service, Partner Data Processing Agreement, and Partner Embed Sub-processors.

  • What the Partner Embed is. The Partner Embed lets a Partner integrate the ISMS Copilot AI assistant into its own product for the Partner's own end-users. In that relationship the Partner is the Controller of its end-users' personal data and ISMS Copilot is the Processor (Art. 28 GDPR). This is a different relationship from the chat product, where ISMS Copilot's own users are the customers, so the Partner Embed has its own Terms, DPA, and sub-processor list at /embed/*. The chat product pages are unchanged.
  • Scope and posture. The Partner ToS covers the AI-output disclaimers, tiers and billing, availability, suspension, the liability cap (the greater of trailing-12-month fees or a EUR 500 floor, claim-gated, never nil), IP and licence, indemnity, confidentiality, trade controls, and the EU AI Act provider/deployer split. The Partner DPA covers the Art. 28(3) processor obligations, general sub-processor authorisation with control-neutral routing within the disclosed envelope (publication-only) and a 30-day advance-notice objection-and-termination remedy reserved for a genuinely new sub-processor or a material control change, international transfers (SCCs Module Three for direct non-EEA legs, OpenRouter as exporter for the onward economy (GLM-4.7) and premium (GLM-5.2) host legs via Art. 28(4) flow-down, EU-US Data Privacy Framework via Google LLC as an additional basis for Vertex), a concluded transfer impact assessment for the US inference legs, the hybrid retention model (operational erasure plus a statutory ledger on Art. 6(1)(c) pseudonymisation), breach notification within 24 hours, and the SCC Annexes.
  • Sub-processors (by tier). Infrastructure and observability (Supabase, Fly.io, Vercel, Sentry, Axiom) plus Mistral (EU) content moderation on every tier. The AI model by tier is: GLM-4.7 via OpenRouter pinned to a closed non-PRC host set (Cerebras, Google Vertex), mandatory zero-retention, on the economy tiers (Free, Starter); on the premium tiers (Growth, Scale, Enterprise) the primary is GLM-5.2, a further open-weights model of Chinese authorship, likewise via OpenRouter pinned to a closed non-PRC host set (Together AI, Fireworks AI, DeepInfra), mandatory zero-retention, with Anthropic (US) as the pre-first-token fallback (SCCs Module Three, standard commercial retention, no zero-retention) and Mistral (EU) as the deeper circuit-breaker failover; and Mistral (EU) on the ADP tier. End-user economy and premium prompts do not reach a PRC endpoint. Stripe processes partner billing data only and is not an end-user-data sub-processor.
  • Consistency with the chat Trust Center. The Partner Embed sub-processor naming, the economy- and premium-tier China posture (each model's first-party PRC endpoint named only as a blocked host), the OpenRouter mandatory-ZDR framing, and the Anthropic retention wording (ordinary deletion up to ~30 days, safety-flagged content up to 2 years, safety-classification scores up to 7 years, no training) mirror the chat product's customer-facing documents. Because both the economy (GLM-4.7) and premium (GLM-5.2) primary models are of Chinese authorship, the model-origin acknowledgment sits in the Partner DPA (§3.3) and ToS (§5) and is also surfaced on the public Partner Embed sub-processor list.
  • Sub-processor changes are control-neutral by default. Within the disclosed OpenRouter / Anthropic / Mistral envelope, ISMS Copilot may route or switch the Partner's AI traffic (and move a tier or cohort between destinations over time) publication-only, with no advance notice, provided prompts are never routed to a PRC endpoint and a selected EU / ADP (Mistral, EU) path stays EU. Only a genuinely new sub-processor or a material control change triggers 30-day advance notice plus the objection-and-termination remedy (Partner DPA §3.2), mirroring the chat DPA §2.4 model. Direct non-EEA legs are on SCCs Module Three; OpenRouter is the exporter for the onward economy (GLM-4.7) and premium (GLM-5.2) host legs via the Art. 28(4) flow-down; EU-US Data Privacy Framework via Google LLC is an additional basis for Vertex.

2026-07-21: xAI (Grok) activated as the default AI provider for paid chat Fast/Think and Beyond (effective 2026-07-21; control-neutral)

Documents touched: customer-facing DATA-PROCESSING-AGREEMENT.md, PRIVACY-POLICY.md, REGISTER-OF-PROCESSING-ACTIVITIES.md, TERMS-OF-SERVICE.md, and the standalone SUB-PROCESSOR-CHANGE-NOTICE-2026-07-21-XAI-GROK-DEFAULT.md; internal ai-system/ZDR-Provider-Tracker.md, data-protection/REGISTER-OF-PROCESSING-ACTIVITIES.md, and the ai-system/evidence/ captures.

  • xAI activated for paid Customer-Content, not added. xAI is already present on the OpenRouter account allowlist and already serves the public, logged-out risk-analysis demo through OpenRouter's "xAI (ZDR)" endpoint. This change documents that existing account state and activates the paid Customer-Content scope; it does not introduce a new provider to the account.
  • New default for paid Fast/Think/Beyond. For paid plans (Plus and above) with Advanced Data Protection off, the default AI provider for the chat Fast and Think modes and the Beyond assistant is now xAI (Grok models) via OpenRouter's "xAI (ZDR)" endpoint, replacing Anthropic as the default for those routes. Anthropic Claude is retained as the automatic pre-first-token failover (Opus for Think, Sonnet for Fast) and remains a disclosed sub-processor. Free, Essential, and null-plan glm-4.7 routing and Advanced Data Protection routing (Mistral, EU) are unchanged.
  • Why control-neutral. As configured and verified 2026-07-19, the "xAI (ZDR)" endpoint operates under mandatory OpenRouter account-level Zero Data Retention (stronger than the Anthropic standard-commercial-API retention it replaces), no-training (account-level training-disallowed plus xAI's published API no-training default), US (non-PRC) jurisdiction, and the same underlying-provider SCC transfer mechanism (xAI's published DPA, EU SCCs Modules 2/3, Irish-law, with OpenRouter's Article 28(4) flow-down). No control is weakened, no new category of personal data is introduced, and Advanced Data Protection (Mistral, EU, zero-retention) remains available to suppress the OpenRouter path entirely. Classified control-neutral under DPA §2.4(c).
  • Notice mechanism. Control-neutral, so notice is by publication in the Trust Center and this change log, with no advance notice period. Customers may object at any time via privacy@ismscopilot.com or enable Advanced Data Protection.
  • Location. OpenRouter publishes a United States footprint for xAI and does not pin the per-request inference region; the underlying-provider SCCs are the operative transfer safeguard. Customers needing a guaranteed EU destination should enable Advanced Data Protection (Mistral, Frankfurt).
  • Companion reconciliations shipped in the same publication. The RoPA sub-processor-change procedure and the "Record Maintenance" change-driven-updates bullet were reconciled to mirror the DPA §2.4 materially-adverse / control-neutral split; the closed-allowlist provider count was corrected to eight where it describes the full Customer-Content destination set (the seven glm-4.7 hosts remain seven for free-tier routing); the stale demo disclosure in RoPA Processing Activity #11 ("public business data only, never customer content") was corrected to reflect design intent rather than a semantic guarantee.

2026-07-19: Unified non-ADP AI-routing envelope, Anthropic retention correction, and the app-managed Plus trial (effective 2026-07-19; control-neutral)

Documents touched: customer-facing PRIVACY-POLICY.md, DATA-PROCESSING-AGREEMENT.md, REGISTER-OF-PROCESSING-ACTIVITIES.md, TERMS-OF-SERVICE.md.

  • Unified non-ADP routing envelope. The non-ADP AI-routing disclosure no longer differentiates by plan: any non-ADP plan (including Free) may be served by Anthropic under its standard commercial API terms or by the zero-retention OpenRouter allowlist, with Mistral (EU) as the failover. The specific provider serving a given request may vary by plan, rollout, and over time. Advanced Data Protection remains the guaranteed EU, zero-retention path. The unification is classified control-neutral under DPA §2.4 (no new sub-processor; no weakening of an existing control), so no advance notice period applies.
  • Anthropic retention corrected. The Anthropic retention statement now reflects its standard commercial API terms: inputs and outputs are ordinarily deleted within about 30 days; content flagged by Anthropic's safety systems may be retained up to 2 years and safety-classification scores up to 7 years; never used for model training.
  • App-managed Plus trial. A 7-day, no-card Plus trial is being introduced. When a trial starts, the account records a free-trial eligibility marker (one trial per account), kept for the life of the account under our legitimate interest in offering the one-time trial fairly and deleted when the account is deleted. The marker and the trial fields are included in the GDPR Art. 15 data export, and you can object at any time via privacy@ismscopilot.com. Trial AI traffic rides the same unified envelope; there is no separate trial carve-out.
  • Web search is live. The authenticated web-search disclosure (dedicated entry below) is effective as of this publication.

2026-07-19: Authenticated web-search Mistral bridge (Mistral web search uses Brave/US) and future Brave-direct notice package (effective 2026-07-19)

Documents touched: customer-facing PRIVACY-POLICY.md, DATA-PROCESSING-AGREEMENT.md, REGISTER-OF-PROCESSING-ACTIVITIES.md, TERMS-OF-SERVICE.md; internal data-protection/REGISTER-OF-PROCESSING-ACTIVITIES.md and data-protection/AUTHENTICATED-WEB-SEARCH-LAUNCH-DECISION-2026-07-13.md. The corresponding Trust Center pages, in-app changelog, customer email, and any help-center mirror must be synchronized when the notice is issued.

  • Product behavior disclosed. Eligible authenticated requests may use a conservative Mistral search-intent check. Search is visible through source provenance and can be disabled by personal and organization policy. Retrieval supplies the current/company-specific evidence; the answering AI reasons and writes using that evidence and separately maintained framework knowledge. Citations support review but are not a correctness guarantee.
  • Mistral bridge for non-ADP discovery. SEARCH_RETRIEVAL_PROVIDER defaults to Mistral for eligible ADP-off search. Mistral discovers provider-attested source URLs and its generated search prose is discarded. The EU Fly.io service exact-fetches referenced pages and passes bounded labeled extracts to the answer model already applicable to the conversation or Beyond run. No additional semantic grounding model receives the draft. Mistral's web search runs on Mistral's stateful Conversations/Agents endpoint, which Mistral excludes from its zero-retention posture, and uses Brave Search (Brave Software, Inc., United States) as its web-search sub-processor; the non-ADP query hop therefore goes Mistral (EU) to Brave (US), is not EU-only and not zero-retention, and standard (non-zero) retention applies. Authenticated web search fails closed under ADP (because Mistral web search is not EU-only or zero-retention), while exact user-selected page/document fetch remains available through EU Fly and the all-Mistral answer topology.
  • Exact fetch is EU and request-scoped. The same hardened Fly service fetches Mistral-attested URLs and exact URLs submitted in Beyond. Each selected public host receives ordinary outbound request metadata. Raw discovery responses, Mistral prose, page text, and search evidence are not persisted. The generated answer and displayed source links follow the existing conversation-retention setting.
  • The Brave-direct route is pending, dark, and not the launch default. This is separate from Brave's launch role as Mistral's web-search sub-processor described above. A proposed future direct Brave route (ISMS Copilot calling the Brave API itself, rather than reaching Brave via Mistral) would send only a bounded latest-request query and no files, memories, workspace context, account identifiers, or user/device identifiers. Brave operates in the United States on AWS, standard query logs may be retained up to 90 days, and SCCs are the transfer mechanism. Brave's DPA excludes Search Query Data from processor scope, so the documents disclose Brave as a limited recipient rather than representing the query processing as covered by Article 28 processor terms.
  • Notice classification and timing. The materially-adverse classification and 30-day advance-notice requirement apply to the future Brave-direct route only (ISMS Copilot calling the Brave API itself), which would create a new US recipient with a different retention and contractual posture under DPA §2.4. 2026-08-12 is the earliest possible activation of that future route only if the notice is actually published and emailed on 2026-07-13; otherwise the activation date moves to at least 30 days after actual notice. That future route also remains subject to founder acceptance of Brave's contract, Search Query Data carve-out, selected plan, and standard retention posture. The launch Mistral-mediated route (where Brave is reached only as Mistral's own web-search sub-processor and is not engaged by ISMS Copilot) is not classified as a materially-adverse baseline-processing change: it is a user-directed, customer-controllable feature (it fires only on the user's own search intent, is disabled under ADP, is controllable by personal and organization policy, and is shown via source provenance), and it is disclosed at launch through the Trust Center, DPA, and in-app changelog when the feature goes live.

Notice status: the Mistral/Fly launch disclosure is PUBLISHED effective 2026-07-19; the feature is live in production. Mistral web search is disclosed as not having the EU-only, zero-retention posture of other Mistral routes: it runs on Mistral's stateful Conversations/Agents endpoint and uses Brave (US) as its web-search sub-processor, so the non-ADP query hop reaches Brave (US) under standard retention. The founder-acceptance decision is the residual Mistral Additional-Product-Terms interpretation risk for persisted links/answers (see the internal launch decision record), not the search-hop location or retention, which are now known. The separate future Brave-direct notice package is not yet published or emailed; the direct-Brave route must remain disabled. The customer-facing documents and this entry were published on 2026-07-19, after the feature went live and the deployment and smoke-test gates recorded in the search launch-readiness document were met.

2026-06-23: Paid-plan AI routing may use the OpenRouter allowlist alongside Anthropic (effective 2026-06-23; control-neutral)

Documents touched: customer-facing DATA-PROCESSING-AGREEMENT.md, PRIVACY-POLICY.md, REGISTER-OF-PROCESSING-ACTIVITIES.md, TERMS-OF-SERVICE.md; internal ai-system/ZDR-Provider-Tracker.md and data-protection/VENDOR-DPA-OPENROUTER-2026-05-05.md. (The OpenRouter underlying-provider allowlist expansion from 4 to 7 and the §2.4 notice-mechanism amendment first noticed on 2026-05-26 are brought into effect together with this change on 2026-06-23, two days ahead of the previously published 2026-06-25 date; those providers have been on the operational allowlist since 2026-05-25, the change is control-neutral, and the objection / Advanced-Data-Protection rights are unchanged. The 2026-06-13 per-session-election proposal recorded below was superseded before publication and never took effect.)

  • Paid-plan routing broadened to mirror the free tier. For paid plans (Plus, Standard, Pro, Business) with Advanced Data Protection off, the closed 7-provider OpenRouter allowlist (Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius) becomes a permitted AI-routing destination alongside Anthropic, for any chat mode. A paid request may be served by Anthropic or by any allowlisted provider, and routing may move between them over time, with no further sub-processor change.
  • Anthropic is not removed. It remains a disclosed paid provider and the circuit-breaker failover context; it is simply no longer the sole paid path.
  • No new sub-processor; controls unchanged. OpenRouter and all seven underlying providers are already disclosed. The same account-level controls (mandatory Zero Data Retention, training-disallowed, publication-disallowed, allowlist, PRC-blocklist) and the same underlying-provider transfer mechanism (SCCs at the underlying-provider layer; DPF for Google Vertex) apply unchanged. Every allowlisted provider is equal to or stronger than Anthropic on retention, training, and jurisdiction.
  • Retention. Unchanged for any paid traffic still served by Anthropic (up to 30 days for abuse monitoring only, not training). Paid traffic served by an allowlisted provider is zero-retention.
  • EU residency. Advanced Data Protection remains the account-level EU-residency guarantee: enabling it routes all of the organization's AI processing to Mistral (EU, Frankfurt) and suppresses the OpenRouter path for every user, regardless of plan or mode.
  • Supersedes Amendment B. The 2026-06-13 Amendment B (a per-session end-user election gating paid-plan overflow routing) was never published or made operative and is superseded in full by this amendment, which replaces the per-session election model with the account-level routing approach above. The Amendment B entry below is retained for historical completeness only.
  • Classified control-neutral. Notice is via Trust Center publication and the in-app changelog, per DPA §2.4. The Customer may object at any time by emailing privacy@ismscopilot.com, and may keep all processing in the EU at any time by enabling Advanced Data Protection.

2026-06-13: DPA Pending Amendment B: OpenRouter scope expansion to paid-plan overflow routing (effective on publication; control-neutral; web-only)

Documents touched: customer-facing DATA-PROCESSING-AGREEMENT.md, PRIVACY-POLICY.md, TERMS-OF-SERVICE.md, REGISTER-OF-PROCESSING-ACTIVITIES.md; internal data-protection/TRANSFER-IMPACT-ASSESSMENT.md, data-protection/REGISTER-OF-PROCESSING-ACTIVITIES.md, and the new data-protection/SUB-PROCESSOR-CHANGE-NOTICE-2026-06-13-OVERFLOW-FALLBACK.md. (This amendment is independent of the 2026-05-26 DPA §2.4 amendment, which is effective 2026-06-25 under its own 30-day notice schedule.)

  • OpenRouter sub-processor scope expanded. The OpenRouter aggregator (already disclosed since 2026-04-27 for free / null-plan users, expanded 2026-05-28 to Essential) gains a third scope: serve paid plans (Plus, Standard, Pro, Business) with ADP off as overflow routing after the 4-hour token cap is reached, restricted to the same closed two-provider subset as Essential (Google Vertex and Cerebras). No new sub-processor is introduced; no new underlying provider; no change to account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, allowlist, PRC-blocklist); no change to transfer mechanism (SCCs at the underlying-provider layer).
  • Activation is per-session, on explicit in-product end-user election. The overflow path does not auto-engage. When a paid-plan user hits the 4-hour token cap in the ISMS Copilot web app, an in-product card offers continuation on the faster overflow model OR continuation by upgrading to a higher-cap plan. The user must click Continue to elect overflow routing, which then applies for the rest of the current 4-hour window or until an additional overflow usage limit is reached, whichever comes first. The election expires automatically at the next 4-hour bin boundary and is re-prompted on the next over-cap request. Without the election, the request is rate-limited and Anthropic remains the only AI sub-processor for the remainder of the session.
  • Traffic from channels without an in-product election surface (such as Slack integrations) is EXCLUDED from the overflow path. Those channels do not provide an in-product election surface that meets the consent semantics above. Paid-plan users on such channels continue to receive the standard rate-limit message at the 4-hour cap; no overflow routing occurs from those requests in v1.
  • §2.4 control-neutral category clarified. The existing control-neutral category (whose listed examples are non-exhaustive) is clarified with a new (b) example: expanding an already-disclosed sub-processor's scope to serve an additional Customer cohort where the underlying-provider subset, account-level controls, and transfer mechanism remain unchanged, and where no Customer Personal Data flows under the expanded scope unless an explicit per-session end-user election is recorded. The OpenRouter overflow scope expansion is an instance of (b).
  • Existing routing unchanged. ADP path (Mistral, EU) is unchanged. Existing paid-plan routing under the cap (Anthropic, US, SCCs) is unchanged. Free-plan and Essential-plan OpenRouter routing is unchanged. Beyond mode (Plus+) is unchanged; over-cap Beyond requests downgrade to the normal flow with a new notice reason that surfaces the cap state and lets the overflow election flow handle the routing.
  • Classified control-neutral. ISMS Copilot classified this scope expansion as a control-neutral change under §2.4. The amendment becomes effective on publication (the dev-to-main release plus the trust-center mirror sync).

Notice mechanism for this change: in-app changelog (blue-point unread indicator) + Trust Center publication on the effective date + a clearly labeled entry in the next monthly product-changelog email. The change is classified as control-neutral under the new §2.4 (b) wording, so the 30-day advance-notification rule for materially-adverse changes does not apply. Customers may object at any time via privacy@ismscopilot.com. The durable EU-only opt-out (Advanced Data Protection Mode → Mistral, Frankfurt) remains available on every plan.

2026-05-26 — DPA §2.4 sub-processor-notice amendment + OpenRouter allowlist expansion (effective 2026-06-25)

Documents touched: PRIVACY-POLICY.md, DATA-PROCESSING-AGREEMENT.md, REGISTER-OF-PROCESSING-ACTIVITIES.md, TERMS-OF-SERVICE.md.

  • DPA §2.4 sub-processor notice mechanism amended. Aligned with industry norm (Anthropic, OpenAI, Vercel) by distinguishing materially-adverse sub-processor changes (which continue to get at least 30 days' advance notice by in-app announcement and email) from control-neutral changes (notified by Trust Center publication and in-app changelog). The privacy bar itself — zero data retention, no training on customer data, no PRC-jurisdiction infrastructure, Advanced Data Protection Mode available on every plan for EU-only processing — is unchanged. Privacy Policy §2 sub-processor paragraph updated to cross-reference the new §2.4 wording.
  • OpenRouter underlying-provider allowlist expanded from four to seven. Under the new §2.4 wording, this is the first control-neutral change: the named providers are now Inceptron, DeepInfra, Cerebras, Google Vertex (the original four) plus Together AI, Fireworks AI, and Nebius. Each addition was evaluated against the same privacy and jurisdiction bar applied to the original four: zero-retention posture for inference, no training on customer data, published DPA, non-PRC jurisdiction, public deployment-region disclosure. Together AI publishes default routing to North America inference data centers; Fireworks AI operates a multi-region fleet (US, EU Frankfurt + Iceland, APAC Tokyo only — no PRC or Hong Kong infrastructure); Nebius runs primary inference in Finland (EU) with US secondary. Region pinning at the per-provider layer is not exposed by OpenRouter's aggregator API; the §3.1.4 PRC-jurisdiction control relies on each provider's published default region NOT being PRC, verified provider-by-provider during this review.
  • Novita AI evaluated and not added. Novita's corporate HQ is recorded as US, but their public materials describe their inference infrastructure only as "20+ locations, 4+ continents" without naming any region. They do not publish a DPA, a sub-processor list, a governing-law clause in their ToS, or a sub-processor enumeration. For a control framed as a Schrems II-style supplementary measure (no Customer Content transits PRC infrastructure), public opacity makes the control unevidenceable. Re-evaluation requires a written commitment on regional pinning and a published DPA.
  • Account-level controls unchanged. Mandatory Zero Data Retention, Free/Paid Training Disallowed, Free Publication Disallowed, and the PRC-jurisdiction blocklist (Alibaba Cloud International, Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, Z.AI) all remain in force.

Notice mechanism for this change: in-app changelog (blue-point unread indicator, visible from 2026-05-26 through 2026-06-25, the full 30-day objection window) + Trust Center publication on 2026-05-26 + a clearly labeled entry titled "Legal/privacy update: DPA amendment and OR allowlist notice" in the May 2026 monthly product-changelog email shipping in the first days of June. Both the DPA amendment and the OR allowlist expansion are effective 2026-06-25, giving customers 30 days to object via privacy@ismscopilot.com. A more detailed internal change record is available on request.

2026-04-29 — Terms of Service

Documents touched: TERMS-OF-SERVICE.md only.

  • Added §5(v) Customer Content confirming that, as between the user and ISMS Copilot, the user retains all rights to outputs they create, review, adapt, or publish using the Services. The clause includes four for-clarity carve-outs covering: (a) no rights granted over the Services or their underlying technology; (b) outputs may not be represented as official standards, certifications, or legal advice; (c) outputs may not be used to assert IP claims over content that infringes third-party rights or that was generated by inputting third-party copyrighted material; and (d) ISMS Copilot retains the existing abuse-detection / QA monitoring carve-out under §11(iii).
  • Closes a customer-raised gap on supplier-assurance IP-ownership clarity. The other three documents in this set are unchanged in this revision.

2026-04-27 — Multi-document update (Privacy Policy, DPA, RoPA, Terms)

Documents touched: PRIVACY-POLICY.md, DATA-PROCESSING-AGREEMENT.md, REGISTER-OF-PROCESSING-ACTIVITIES.md, TERMS-OF-SERVICE.md.

  • OpenRouter underlying providers named. The previous vague "United States" reference is replaced with a closed four-provider allowlist (Inceptron, DeepInfra, Cerebras, Google Vertex). Account-level controls are disclosed: mandatory Zero Data Retention; training disallowed (free + paid); publication disallowed (free); PRC-jurisdiction blocklist.
  • Active vs Reserved sub-processor split. OpenAI, X.AI, and Google Gemini are documented as Reserved — code paths exist but no user-facing flow invokes them — and their activation requires customer notice. The Privacy Policy lists Active sub-processors only.
  • Slack (heygrc bot) disclosed as a Customer-Activated Integration. Slack Technologies, Inc. only becomes a sub-processor for a customer's data when that customer's organisation owner explicitly installs the bot. The 30-day advance-notice rule for Active sub-processors does not apply because activation requires explicit customer-side action. New processing activity (RoPA #10), new data-subject category (Slack workspace users without ISMS Copilot accounts), and a ToS §7(iv) acknowledgment.
  • Anthropic retention factually corrected. The prior "zero retention" wording for Anthropic on the paid default path is replaced with the accurate 30-day commercial-API abuse-monitoring cache. Customers requiring zero retention are directed to enable Advanced Data Protection (Mistral, EU).
  • "No-training" wording tightened. Prior wording implied a signed bilateral addendum with Anthropic and Mistral. New wording reflects what is actually relied on: each provider's published commercial-API terms prohibit training on customer content.
  • Per-provider transfer-mechanism stack documented in DPA §3 (SCCs / SCCs + EU-US Data Privacy Framework / EU residency, depending on provider).
  • Moderation correction. Moderation always runs on Mistral (EU, zero retention), regardless of ADP. The Privacy Policy and DPA disclose the metadata-only retention scope of moderation_events and the thread-deletion lock for flagged threads (with the Article 17 email-mediated path for content within flagged threads).
  • ToS §11(iii) and §7(i) tightened — the prior "without anonymization and strict safeguards" carveout is removed, and the prior blanket EU-residency disclaimer is replaced with a factual routing description matching the Privacy Policy and DPA.
  • Advanced Data Protection (ADP) framed as the durable in-product opt-out for any user who needs fully EU-based AI processing.

A 30-day customer objection window for the OpenRouter sub-processor change runs through 2026-05-27.